Skip to content

fix: patch defu prototype pollution CVE via pnpm override#3841

Open
jpr5 wants to merge 1 commit intomainfrom
fix/issue-3631
Open

fix: patch defu prototype pollution CVE via pnpm override#3841
jpr5 wants to merge 1 commit intomainfrom
fix/issue-3631

Conversation

@jpr5
Copy link
Copy Markdown
Contributor

@jpr5 jpr5 commented Apr 12, 2026

Closes #3631

Add pnpm override to force defu >= 6.1.5 (was 6.1.4), resolving the prototype pollution vulnerability.

Split from #3838.

Add pnpm override to force defu >= 6.1.5 (was 6.1.4), resolving the
prototype pollution vulnerability.
@vercel
Copy link
Copy Markdown
Contributor

vercel bot commented Apr 12, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
chat-with-your-data Ready Ready Preview, Comment Apr 12, 2026 10:20pm
docs Ready Ready Preview, Comment Apr 12, 2026 10:20pm
form-filling Ready Ready Preview, Comment Apr 12, 2026 10:20pm
research-canvas Ready Ready Preview, Comment Apr 12, 2026 10:20pm
travel Ready Ready Preview, Comment Apr 12, 2026 10:20pm

Request Review

@github-actions
Copy link
Copy Markdown
Contributor

📣 Social Copy Generator

Generate social media copies (Twitter/X, LinkedIn, Blog Post) for this PR using Claude.

  • Generate social media copies

@changeset-bot
Copy link
Copy Markdown

changeset-bot bot commented Apr 12, 2026

⚠️ No Changeset found

Latest commit: 1dbc901

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vulnerability in CopilotKit project

1 participant